Password security guide

Password Manager Guide

A password manager makes unique random passwords practical, but the vault, master credential, devices and recovery plan still require careful setup.

What a password manager solves

The manager creates and stores a different credential for every account, reducing reuse and memory pressure. Autofill can help identify the expected domain, and security reports can flag duplicate, weak or known-compromised entries. Secure sharing features are safer than sending passwords in chat.

A manager does not make every risk disappear. A compromised unlocked device, malicious extension, phishing approval or weak recovery process can still expose accounts.

How to evaluate a password manager

AreaQuestions to ask
ArchitectureWhere does encryption occur? What can the provider decrypt?
UpdatesAre clients maintained and security issues handled transparently?
AuthenticationDoes it support strong MFA, passkeys or security keys?
RecoveryWhat happens if the master credential or device is lost?
PortabilityCan you export and import without losing fields?
DevicesAre the browsers and operating systems you use supported?

Create a strong master credential

The master credential must be unique and resistant to guessing. A long randomly generated passphrase can balance strength and memorability. Do not reuse an account password, a familiar quotation or a variation of an old master password.

Practice it before depending on memory, but never type it into unrelated sites. Some managers cannot recover it by design, so understand the provider model before migration.

Enable strong MFA and secure recovery

Prefer a phishing-resistant factor such as a security key or supported passkey, with a second safe method for recovery. Authenticator apps are also useful. Keep recovery codes or emergency kits offline in a protected location separate from the main device.

Do not remove the old factor until the new one works from another authorized device. Review account email and phone recovery details at the same time.

Migrate without lockout

  1. Set up the manager and recovery first.
  2. Import or add a small group of accounts.
  3. Verify URLs and remove obsolete duplicates.
  4. Replace reused passwords, beginning with email and financial accounts.
  5. Test sign-in before deleting old records.
  6. Securely remove temporary export files.

Exports are often plaintext. Create them only when necessary, keep them briefly and do not place them in an automatically synchronized folder.

Browser manager, standalone manager or enterprise system?

Built-in browser managers can be practical for individuals using one ecosystem. Standalone services may offer broader platform support, sharing and recovery features. Organizations need identity lifecycle, policy, audit, delegated recovery and access revocation.

The label matters less than the actual architecture, maintenance and fit. Avoid making a choice solely from affiliate reviews or a feature count.

Protect the devices that unlock the vault

Use current operating systems, device encryption, screen lock and a separate device login. Remove unneeded browser extensions and review manager sessions. Biometrics usually unlock a device-protected credential; they do not replace the vault encryption and recovery model.

Sharing passwords safely

Prefer separate user accounts and role-based access. When a credential must be shared, use the manager sharing function so access can be granted and revoked per person. Avoid shared master accounts, spreadsheets and messages.

Rotate a shared credential after a person or vendor loses authorization. Keep an inventory of service owners and recovery contacts.

What to do after a provider incident

Read the provider notice and technical details before taking blanket action. Update clients, review sessions, verify MFA and follow provider-specific rotation guidance. If vault data or account access may be exposed, prioritize the master credential and highest-value stored accounts.

A strong unique master credential and properly designed vault encryption provide important defense, but incident facts determine the response.

Password manager setup checklist

  • Unique master credential.
  • Strong MFA with a backup method.
  • Recovery material stored separately.
  • Current clients from official sources.
  • Verified import and export process.
  • No lingering plaintext export.
  • Emergency access plan appropriate to the user or business.

Cloud-synced, local and self-hosted tradeoffs

Cloud synchronization simplifies multi-device access and recovery but adds a provider account and service availability dependency. A local vault offers direct file control but makes backup, synchronization and conflict handling the user’s responsibility. Self-hosting adds server maintenance, monitoring and secure update obligations.

Choose the model you can operate reliably. A theoretically elegant vault that is never backed up, patched or available during recovery is a poor practical choice.

Emergency access and inheritance

Individuals should decide how a trusted person can reach critical accounts after incapacity without giving them routine access today. Businesses need a documented break-glass process with multiple approvers, logging and prompt credential rotation after use.

Provider emergency-access features, sealed recovery material and legal estate planning solve different parts of the problem. Test the process with non-sensitive examples.

Audit the vault without creating new risk

Use built-in duplicate and weak-password reports locally or within the trusted provider workflow. Avoid exporting the vault to an unknown “security checker.” Review old accounts, incorrect URLs, duplicate records, stale sharing and obsolete recovery notes. Fix a manageable batch, confirm access, then continue.

Sources and further reading

Create a random master passphraseUse independent EFF-list words, then follow the manager recovery guidance.Open the tool →Generate unique account passwordsReplace reused entries one account at a time.Open the tool →
Written and reviewed by Gabor Kohanyi

Technical claims are checked against the cited primary standards and official service documentation. Corrections are handled under the editorial policy.